GDPR fines and notices


The General Data Protection Regulation is a European Union regulation that specifies standards for data protection and electronic privacy in the European Economic Area, and the rights of European citizens to control the processing and distribution of personally-identifiable information.
Violators of GDPR may be fined up to €20 million, or up to 4% of the annual worldwide turnover of the preceding financial year, whichever is greater. The following is a list of fines and notices issued under the GDPR, including reasoning.

Fines and notices

DateOrganisationAmountIssued byReason
2018-10Hospital do Barreiro€400,000Portugal "...based on access policies to databases, which allowed technicians and physicians to consult patients’ clinical files, without proper authorization."
2018-11-21Knuddels.de €20,000Germany "...unauthorized access to and disclosure of personal data of around 330,000 users, including passwords and email addresses."
2019-01-21Google LLC€50,000,000France Insufficient transparency, control, and consent over the processing of personal data for the purposes of behavioural advertising.
2019-03-07Unnamed bank€1,560Hungary Failure to erase and correct data at the request of the data subject.
2019-03-07Unnamed debt collector€1,560Hungary
Breaching the principles of transparency and data minimisation.
2019-03-15Bisnode €220,000Poland
Covert scraping of personal data.
2019-03-16Lower Silesian Football Association€13,000Poland
Listing personal information of 585 referees on its website.
2019-04-04Rousseau €50,000Italy Failing to protect users' personal data.
2019-05-08The Municipality of Bergen€170,000Norway
File with login credentials for 35,000 students and employees found in a public storage area.
2019-05-16MisterTango UAB €61,500Lithuania Processing more personal data than is necessary for effecting of the payment.
2019-05-28Unnamed Belgian mayor€2,000Belgium Misuse of personal data collected for local administrative purposes for election campaign purposes.
2019-06La Liga€250,000Spain Poorly disclosing purpose for requesting GPS and microphone permissions within the football league's mobile app. When the app was open, it transmitted the user's location if it detected an acoustic fingerprint embedded within game telecasts. This was used to help pinpoint the locations of venues that may be screening the games from unauthorized feeds.
2019-06-11IDDesign A/S DKK 1,500,000Denmark Failure to delete personal data from an older system: processing personal data for a longer time than necessary.
2019-06-18Unnamed police officer€1,400Germany Autonomously processing personal data for non-legal purposes.
2019-06-18Sergic €400,000France
Failure to implement appropriate security measures; failure to define appropriate data retention periods for the personal data of unsuccessful rental candidates.
2019-06-18Uniontrad Company €20,000France
Excessive video surveillance of employees; single, shared password for messaging system; ignoring earlier CNIL order to change practices.
2019-06-24EE £100,000UK Sending over 2.5 million direct marketing messages to its customers, without consent.
2019-06-27UniCredit Bank Romania€130,000Romania Failure to implement appropriate technical and organisational measures
2019-07-08British Airways£183,000,000UK Use of poor security arrangements that resulted in a 2018 web skimming attack affecting 500,000 consumers. Was later reduced to £20 million
2020-10-30Marriott International£18,400,000UK Failure to keep millions of customers’ personal data secure
2019-07-03Cathay Pacific£500,000UK Failure to protect the security of its customers’ personal data. Between October 2014 and May 2018 Cathay Pacific’s computer systems lacked appropriate security measures which led to customers’ personal details being exposed
2019-07-16HagaZiekenhuis€460,000The Netherlands Insufficient security of medical records
2019-07-25Active Assurances€180,000France
Failure to implement appropriate security measures.
2019-07-25PricewaterhouseCoopers€150,000Greece
Unlawful processing of employee data.
2019-08-21Skellefteå High School Board€20,000Sweden
Using facial recognition technology to monitor the attendance of students in school on an invalid legal basis; processing sensitive biometric data unlawfully and failure to do an adequate impact assessment including seeking prior consultation with the Swedish DPA.
2019-??-??Unnamed company€3,135Hungary
Infringing a data subject's access rights.
2019-08-12Unnamed medical company€55,000Austria
Not appointing a DPO, not publishing its contact details or reporting those to the supervisory authority, obligatory consent of data subjects, not providing information, no DPIA despite handling sensitive data.
2019-08-12Unnamed online retailer€7,000Latvia
Nonconformity with data subjects rights to erasure and non-cooperation with the supervisory authority.
2019-09-19Unnamed retailer€10,000Belgium Demanding an electronic identity card to create a customer loyalty card.
2019-10-17Vueling Airlines€30,000Spain Failing to obtain valid consent to process customer cookies, as per privacy notice.
2019-12-091&1 Ionos€9,550,000Germany
Insufficient protection of personal data, failing to put “sufficient technical and organizational measures” in place to protect customer data in its call centers. Violation of article 32 of GDPR
2019-12-17Doorstep Dispensaree£275,000UK "cavalier attitude to data protection”, having left 500,000 patient records in an unsecured location
2020-01-15TIM S.p.A.€27,800,000Italy Unlawful processing for marketing purposes
2020-03-10Google LLCSEK 75 M
Sweden Right-to-be-forgotten violations
2020-07-06BKR€840,000The Netherlands Failing to give access to personal data free of charge, failing to provide easy means of accessing the data, putting unreasonable limits on the number of requests per individual
2020-07-14Google LLC €600,000Belgium
Failure to respect a citizen's right to be forgotten.
2020-10-01H&M€35,300,000Germany Illegal surveillance of several hundred employees
2020-12-10Amazon Europe Core Sarl€35,000,000France Deposit of cookies without obtaining consent and lack of information provided to users
2020-12-10Google LLC€60,000,000France Deposit of cookies without obtaining consent, lack of information provided to users and defective "opposition" mechanism
2020-12-10Google Ireland Limited€40,000,000France Deposit of cookies without obtaining consent, lack of information provided to users and defective "opposition" mechanism
2021-01-26Grindr LLCNOK 65 M
Norway Sharing special category data without valid consent
2021-03-10Filigrana Comunicación€8,000Spain Violation of Article 6, 6, 13 and 14 GDPR by collecting and re-using data from the Andalusian Education Department without a legitimate basis, and not fulfilling their information obligations.
2021-03-17Miljø- og Kvalitetsledelse AS€3,500 Norway Violation of Article 6 and Article 5 of the GDPR by sharing a CCTV recording of a data subject vandalising a property with the data subject's employer, without a legal basis.
2021-03-18Air Europa Líneas Aéreas S.A.€600,000Spain infringement of Articles 32 and 33 GDPR, due to the lack of appropriate technical and organisational measures and of an adequate level of security and due to the delay in the notification of a personal data breach.
2021-03-22FURNISHYOURSPACE SL€3,000Spain Infringing the Spanish Law regulating cookies after an investigation launched due to a complaint referred by the Berlin DPA, for offering unclear information and not giving the option of rejecting the cookies.
2021-03-24CP&A B.V.€15,000The Netherlands Violation of Article 4 GDPR, Article 9 GDPR and Article 32 GDPR by processing the health data of sick employees, and for failing to implement appropriate security measures regarding such processing
2021-04-07Orange Espagne, S.A.U.€150,000 Spain Violation of Articles 6 and 7 GDPR, as well as Article 21 LSSI, by sending bulk unsolicited commercial communications without adequately obtaining the consent of the users.
2021-04-14Natural person €3000Spain Violating Articles 5 and 13 GDPR in relation to a video surveillance system in an apartment building.
2021-04-15Vodafone Espana, S.A.U.€150,000 Spain Violation of Article 6 GDPR by processing personal data without consent or any other legal basis. When imposing the fine, the AEPD took into account:
  • The type of data affected: basic identifiers such as names, surnames, phone number.
  • The relation between the processing and the business activities of the respondent.
  • The previous fines on the same grounds.
  • The lack of diligence regarding the erasure request.
The AEPD finally fined Vodafone €150,000, that was reduced to €90,000 due to the assumption of responsibility and the early payment.
2021-04-22Cyfrowy Polsat Spółka Akcyjna€250,000Poland Violation of Articles 24 and 32 and GDPR by not implementing appropriate technical and organisational measures to ensure the security of personal data when cooperating with a courier company
2021-05-04EDP Comercializadora, S.A.U.€1,500,000Spain Violation of Articles 6, 13, 22 and 25 GDPR by not providing sufficient information to data subjects, and for not implementing adequate measures to avoid or mitigate risks related to the data processing.
2021-05-04EDP ENERGÍA, S.A.U.€1,500,000Spain Violation of Articles 6, 13, 22 and 25 GDPR by not providing sufficient information to data subjects, and for not implementing adequate measures to avoid or mitigate risks related to the data processing.
2021-05-06Owner's association in Iasi€500 Romania Violation of Articles 58, 58, 83 GDPR as well as of Article 8 of Government Ordinance No 2/2001, by violating the obligation to cooperate with the DPA during an investigation by failing to provide the information requested
2021-05-11PVV €7,500The Netherlands Violation of Articles 4, 9 GDPR and 33 GDPR by unauthorised disclosure of a mailing list containing 101 email addresses, and failing to notify this breach to the DPA. The email addresses constituted special category data revealing political party opinions.
2021-05Locatefamily.com€525,000The Netherlands Failure to appoint a representative pursuant to article 27
2021-06-16Amazon Europe Core Sarl€746,000,000Luxembourg The largest fine for violating GDPR at the time. Related to targeted advertising.
2021-09-02WhatsApp Ireland Ltd€225 MIreland
2021-12-16Psykoterapiakeskus Vastaamo€608,000FinlandFailure to protect sensitive medical data.
2022-12-14Viking Line€230,000FinlandThe Office of the Data Protection Ombudsman's Sanctions Board has imposed an administrative fine on Viking Line Oy Abp for data protection violations related to the processing of its employees' health data.
2023-05-12Meta Platforms€1.2 billionIrelandTransferring data from the European Union to the United States without adequate privacy protections
2024-12-09Sky Italia€842,062Italia Violations in telemarketing activities
2024-10-23Selectra€80,000Italia Unlawful processing, data minimization, and storage limitation principles